
APT28 Cracked-Software Lure Rode 16-Month-Old C2 Infrastructure
A single Windows executable posing as five pirated applications reached 37 submission sources in twelve days, backed by C2 infrastructure assembled more than a year before the payload appeared. The campaign, attributed to Russian state-aligned APT28, deploys a stealer-trojan with layered evasion that partially defeated automated sandbox analysis.
A single Windows executable masquerading as five popular pirated applications reached 37 independent submission sources within twelve days of its first appearance — not because the operator rushed the deployment, but because the infrastructure waiting to receive it had been quietly assembled more than a year in advance. The C2 certificate was minted in January 2025. The domains were batch-registered in April 2026. The payload surfaced in June 2026.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read